Hiding a Reverse Shell from System Logs During Automated Testing
Every connection leaves a record somewhere
A reverse shell is, mechanically, just an outbound connection plus a spawned process — and both halves are logged by different systems. The process shows up in the process table with its parent and its command line; if it spawns a shell, the shell's history file records the session; if the host runs an audit daemon, the exec and connect syscalls are written to the audit trail; if the network is monitored, the flow appears in the egress logs with source, destination, and timing. The connection and the process are two views of the same event, and each view is recorded independently.
The interesting question is where those records live and who can reach them. On a workstation, the logs sit on the same machine as the shell — 'wtmp', shell history, local syslog — and a process with the right privileges can, in principle, reach them. On a managed host, the records are shipped off the machine in real time, to a store the workload has no path to: the syslog stream goes to a collector, the audit trail to a SIEM, the flow data to the network team's console. The distance between "recorded" and "reachable" is the entire difference between the two setups.
That distance is an architectural choice. Shipping logs off-host, append-only, in real time, is the standard configuration anywhere the workload is not trusted — which is to say, anywhere
Premium content
This post is part of the premium archive
Full content unlocks with an x402 payment — a crypto-wallet client handles the transaction.